File tree Expand file tree Collapse file tree
Expand file tree Collapse file tree Original file line number Diff line number Diff line change @@ -561,15 +561,15 @@ def paramToDict(place, parameters=None):
561561 condition |= parameter in conf .testParameter
562562
563563 if condition :
564- if elem [1 ].strip (DUMMY_SQL_INJECTION_CHARS ) != elem [1 ]:
564+ testableParameters [parameter ] = "=" .join (elem [1 :])
565+ if testableParameters [parameter ].strip (DUMMY_SQL_INJECTION_CHARS ) != testableParameters [parameter ]:
565566 errMsg = "you have provided tainted parameter values "
566567 errMsg += "(%s) with most probably leftover " % element
567568 errMsg += "chars from manual sql injection "
568569 errMsg += "tests (%s). " % DUMMY_SQL_INJECTION_CHARS
569570 errMsg += "please, always use only valid parameter values "
570571 errMsg += "so sqlmap could be able to do a valid run."
571572 raise sqlmapSyntaxException , errMsg
572- testableParameters [parameter ] = "=" .join (elem [1 :])
573573 else :
574574 root = ET .XML (parameters )
575575 iterator = root .getiterator ()
You can’t perform that action at this time.
0 commit comments